Objective:
Recommended Control 11:
Recommended Control 12:
Recommended Control 13:
Recommended Control 14:
Recommended Control 15:
Recommended Control 16:
Recommended Control 17:
Recommended Control 18:
Recommended Control 19:
Recommended Control 20:
Recommended Control 21:
Recommended Control 22:
Information Technology Security Managers (ITSM) provide
information security leadership and management within their
agency
to support and enforce information security policies
ITSMs should provide leadership and direction for the integration
of information security strategies and architecture with agency
business and ICT strategies and architecture
ITSMs should provide technical and managerial expertise for the
administration of information security management tools
ITSMs should work with the CISO to develop information security
budget projections and resource allocations based on short‐term
and long‐term goals and objectives
ITSMs should coordinate, measure and report on technical aspects
of information security management to CISO
ITSMs should monitor and report to CISO on compliance with
information security policies, as well as the enforcement of
information security policies within the agency
ITSMs should provide regular reports on information security
incidents and other areas of particular concern to the CISO
ITSMs should assess and report to CISO on threats, vulnerabilities,
and residual security risks and recommend remedial actions
ITSMs should assist system owners and security personnel in
understanding and responding to audit failures reported by
auditors
ITSMs should assist and guide the disaster recovery planning team
in the selection of recovery strategies and the development,
testing and maintenance of disaster recovery plans
ITSMs should provide or arrange for the provision of information
security awareness and training for all agency personnel
ITSMs should provide expert guidance on security matters for ICT
projects
ITSM should keep the CISO and system owners informed with up‐
to‐date information on current threats
ITSMs are executives within an agency that act as a conduit between the strategic directions
provided by the CISO and the technical efforts of systems administrators. The main area of
responsibility of an ITSM is that of the administrative and process controls relating to information
security within the agency.
When agencies outsource their ICT services, ITSMs should be independent of any company
providing ICT services. This will prevent any conflict of interest for an ITSM in conducting their
duties.
16